Skip to content
Discussion options

You must be logged in to vote

I don't think Wazuh HIDS rules update anywhere near as frequently as NIDS rules, so this doesn't come up very often. If there is a rule or rules that you would like to add, you can add them to local_rules.xml as shown here:
https://docs.securityonion.net/en/2.3/wazuh.html#tuning-rules

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Comment options

You must be logged in to vote
5 replies
@dougburks
Comment options

@wildlyunder
Comment options

@dougburks
Comment options

@wildlyunder
Comment options

@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants